Log Name: Microsoft-Windows-Sysmon/Operational
Source: Microsoft-Windows-Sysmon
Date: 24/01/2022 21:31:17
Event ID: 15
Task Category: File stream created (rule: FileCreateStreamHash)
Level: Information
Keywords:
User: SYSTEM
Computer: User-Surface.domain.local
Description:
File stream created:
RuleName: -
UtcTime: 2022-01-24 21:31:17.143
ProcessGuid: {d754d8c4-1aa4-61ef-e04b-000000004900}
ProcessId: 12172
Image: C:\Program Files\Google\Chrome\Application\chrome.exe
TargetFilename: C:\Users\user\Downloads\2022\Test (8).ps1
CreationUtcTime: 2022-01-24 21:31:16.192
Hash: MD5=616FF391A0912B09B787100AE33900EE,SHA256=000000000,IMPHASH=00000000000000000000000000000000
Contents: $IE=new-object -com internetexplorer.application $IE.navigate2("www.microsoft.com") $IE.visible=$true
User: DOMAIN\user
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Sysmon" Guid="{5770385f-c22a-43e0-bf4c-06f5698ffbd9}" />
<EventID>15</EventID>
<Version>2</Version>
<Level>4</Level>
<Task>15</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2022-01-24T21:31:17.1438361Z" />
<EventRecordID>32278</EventRecordID>
<Correlation />
<Execution ProcessID="5188" ThreadID="7636" />
<Channel>Microsoft-Windows-Sysmon/Operational</Channel>
<Computer>User-Surface.domain.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="RuleName">-</Data>
<Data Name="UtcTime">2022-01-24 21:31:17.143</Data>
<Data Name="ProcessGuid">{d754d8c4-1aa4-61ef-e04b-000000004900}</Data>
<Data Name="ProcessId">12172</Data>
<Data Name="Image">C:\Program Files\Google\Chrome\Application\chrome.exe</Data>
<Data Name="TargetFilename">C:\Users\user\Downloads\2022\Test (8).ps1</Data>
<Data Name="CreationUtcTime">2022-01-24 21:31:16.192</Data>
<Data Name="Hash">MD5=616FF391A0912B09B787170AE33903EE,SHA256=E2A17C30A21F9D8430FDFF09CCD0AA71E261CE9E9188D8F2EC54AE8593F725CA,IMPHASH=00000000000000000000000000000000</Data>
<Data Name="Contents">$IE=new-object -com internetexplorer.application $IE.navigate2("www.microsoft.com") </Data>
<Data Name="User">DOMAIN\user</Data>
</EventData>
</Event>