Investigating with Splunk

12256

A1berto

HKLM\SAM\SAM\domains\acounts\users\names\a1berto

alberto

 C:\Windows\System32\wbem\wmic.exe"/note:workstation6 process call create -net1 user /add A1berto paw0rd1

0

james.browne

79

hxxp[://]10[.]10[.]10[.]5[.]/news[.]php