Windows Analysis Report
Cerberus.exe

Overview

General Information

Sample name: Cerberus.exe
Analysis ID: 1417291
MD5: dacc6bcf2b73aa547cfd15c8c2d6d769
SHA1: cb4d78891465185d8e89dc652c9e0f240bec5c5f
SHA256: 1725fcfb014a9dc018d70308b32f05947243b626345b3e35dfa285e668043d1d
Infos:

Detection

Score: 7
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Binary contains a suspicious time stamp
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Tries to load missing DLLs

Classification

Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst\include\README.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes\README.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\wheel-0.38.4.dist-info\LICENSE.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\docutils\parsers\rst\include\README.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\docutils\writers\s5_html\themes\README.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\wheel-0.38.4.dist-info\LICENSE.txt Jump to behavior
Source: Cerberus.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Binary string: api-ms-win-crt-locale-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041785502.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494936977.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\pythoncom.pdb source: Cerberus.exe, 00000003.00000002.1333435908.00007FFA2E4AE000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\pywintypes.pdb** source: Cerberus.exe, 00000003.00000002.1341889125.00007FFA4B6D0000.00000002.00000001.01000000.0000000D.sdmp, Cerberus.exe, 00000015.00000002.2359656832.00007FFA33065000.00000002.00000001.01000000.00000035.sdmp
Source: Binary string: api-ms-win-crt-runtime-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042388903.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495734423.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\imageformats\qsvg.pdb source: Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1475425345.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\iconengines\qsvgicon.pdb source: Cerberus.exe, 00000000.00000003.1030266270.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1473876495.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\generic\qtuiotouchplugin.pdb source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1473593522.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-file-l1-2-0.pdb source: Cerberus.exe, 00000000.00000003.1039764961.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490325210.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_hashlib.pdb source: Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1346818337.00007FFA52FD5000.00000002.00000001.01000000.0000000A.sdmp, Cerberus.exe, 00000013.00000003.1487316367.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360902164.00007FFA4B4E5000.00000002.00000001.01000000.00000032.sdmp
Source: Binary string: ucrtbase.pdb source: Cerberus.exe, 00000003.00000002.1345128415.00007FFA50395000.00000002.00000001.01000000.00000004.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1474747129.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-memory-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040310667.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491482836.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-debug-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039505205.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489805185.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32trace.pdb source: Cerberus.exe, 00000013.00000003.1521610524.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_overlapped.pdb source: Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488032558.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041062292.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493421050.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-filesystem-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041578087.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494558175.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_distutils_findvs.pdb source: Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486840418.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build\cpython37\externals\openssl-1.1.0h\tmp64dll\libcrypto-1_1-x64.pdb source: Cerberus.exe, 00000003.00000002.1337113943.00007FFA2E6FA000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\select.pdb source: Cerberus.exe, 00000003.00000002.1346128348.00007FFA50E03000.00000002.00000001.01000000.00000011.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360356467.00007FFA4AA53000.00000002.00000001.01000000.00000039.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_contextvars.pdb source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486077976.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32api.pdb source: Cerberus.exe, 00000003.00000002.1342478132.00007FFA4C9A3000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042499310.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495915120.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: Cerberus.exe, 00000000.00000003.1020697132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1464910511.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-heap-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039988364.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490811944.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-util-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041223693.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493753211.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-synch-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040899040.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493074778.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041474837.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494393244.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\styles\qwindowsvistastyle.pdb%% source: Cerberus.exe, 00000003.00000002.1282991340.00007FFA2B3F7000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\styles\qwindowsvistastyle.pdb source: Cerberus.exe, 00000003.00000002.1282991340.00007FFA2B3F7000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: api-ms-win-core-errorhandling-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039597661.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489974962.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vcruntime140.amd64.pdbGCTL source: Cerberus.exe, 00000000.00000003.1036526898.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1347450263.00007FFA5335E000.00000002.00000001.01000000.00000006.sdmp, Cerberus.exe, 00000013.00000003.1484861162.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360787359.00007FFA4B42E000.00000002.00000001.01000000.0000002E.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1474747129.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_multiprocessing.pdb source: Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1487819498.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-processthreads-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040533959.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491997872.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-console-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039351663.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489453698.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_ctypes.pdb source: Cerberus.exe, 00000003.00000002.1347129083.00007FFA53334000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: api-ms-win-core-file-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039684455.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490151420.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\generic\qtuiotouchplugin.pdb source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1473593522.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-convert-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041397947.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494087186.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdbT source: Cerberus.exe, 00000003.00000002.1304279470.00007FFA2C746000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Gui.pdb source: Cerberus.exe, 00000003.00000002.1296443402.00007FFA2C00A000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\python37.pdb source: Cerberus.exe, 00000003.00000002.1328749112.00007FFA2D528000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\_win32sysloader.pdb source: Cerberus.exe, 00000000.00000003.1039271526.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489289646.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-profile-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040684530.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1492561174.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ucrtbase.pdbUGP source: Cerberus.exe, 00000003.00000002.1345128415.00007FFA50395000.00000002.00000001.01000000.00000004.sdmp
Source: Binary string: C:\build\cpython37\externals\openssl-1.1.0h\tmp64dll\libcrypto-1_1-x64.pdbo source: Cerberus.exe, 00000003.00000002.1337113943.00007FFA2E6FA000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: vcruntime140.amd64.pdb source: Cerberus.exe, 00000000.00000003.1036526898.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1347450263.00007FFA5335E000.00000002.00000001.01000000.00000006.sdmp, Cerberus.exe, 00000013.00000003.1484861162.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360787359.00007FFA4B42E000.00000002.00000001.01000000.0000002E.sdmp
Source: Binary string: api-ms-win-crt-time-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042681893.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1496303650.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_queue.pdb source: Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1345978475.00007FFA50DF3000.00000002.00000001.01000000.00000012.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2359888076.00007FFA33263000.00000002.00000001.01000000.0000003A.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdbBB source: Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1476135310.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\platformthemes\qxdgdesktopportal.pdb source: Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1479519653.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-handle-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039914529.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490648135.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: Cerberus.exe, 00000000.00000003.1010418304.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1452032998.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_lzma.pdbMM source: Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1343458423.00007FFA502C4000.00000002.00000001.01000000.00000009.sdmp, Cerberus.exe, 00000013.00000003.1487538290.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2355865494.00007FFA2CF68000.00000002.00000001.01000000.00000031.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdb source: Cerberus.exe, 00000003.00000002.1304279470.00007FFA2C746000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdb source: Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1476135310.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-synch-l1-2-0.pdb source: Cerberus.exe, 00000000.00000003.1040978083.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493250955.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qgif.pdb source: Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1474216247.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\pythoncom.pdb}},GCTL source: Cerberus.exe, 00000003.00000002.1333435908.00007FFA2E4AE000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_bz2.pdb source: Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1346639585.00007FFA5114F000.00000002.00000001.01000000.00000008.sdmp, Cerberus.exe, 00000013.00000003.1485461386.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360667127.00007FFA4B40F000.00000002.00000001.01000000.00000030.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32pdh.pdb source: Cerberus.exe, 00000013.00000003.1521389099.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-processenvironment-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040459680.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491828013.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-datetime-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039423592.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489629042.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_lzma.pdb source: Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1343458423.00007FFA502C4000.00000002.00000001.01000000.00000009.sdmp, Cerberus.exe, 00000013.00000003.1487538290.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2355865494.00007FFA2CF68000.00000002.00000001.01000000.00000031.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_socket.pdb source: Cerberus.exe, 00000003.00000002.1346315682.00007FFA51129000.00000002.00000001.01000000.00000010.sdmp, Cerberus.exe, 00000015.00000002.2360164022.00007FFA4AA19000.00000002.00000001.01000000.00000038.sdmp
Source: Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041302528.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493914313.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtga.pdb source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1475756466.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32event.pdb source: Cerberus.exe, 00000013.00000003.1521151445.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-localization-l1-2-0.pdb source: Cerberus.exe, 00000000.00000003.1040222688.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491327022.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-math-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041869110.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495112300.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: Cerberus.exe, 00000000.00000003.1040606049.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1492217227.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qicns.pdb source: Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1474496726.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\pyexpat.pdb source: Cerberus.exe, 00000003.00000002.1340267049.00007FFA4B423000.00000002.00000001.01000000.0000000F.sdmp, Cerberus.exe, 00000015.00000002.2353918702.00007FFA2CBE3000.00000002.00000001.01000000.00000037.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32wnet.pdb source: Cerberus.exe, 00000013.00000003.1522420961.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040382883.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491658121.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-multibyte-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041969980.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495315228.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-utility-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042763134.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1496482072.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-rtlsupport-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040752593.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1492735859.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-timezone-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041137335.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493585475.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-string-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040830660.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1492902278.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-file-l2-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039846078.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490487800.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-process-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042067758.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495512088.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-libraryloader-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040148966.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491149058.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\python3.pdb source: Cerberus.exe, 00000003.00000002.1345799328.00007FFA50512000.00000002.00000001.01000000.00000014.sdmp, Cerberus.exe, 00000013.00000003.1516386598.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\pywintypes.pdb source: Cerberus.exe, 00000003.00000002.1341889125.00007FFA4B6D0000.00000002.00000001.01000000.0000000D.sdmp, Cerberus.exe, 00000015.00000002.2359656832.00007FFA33065000.00000002.00000001.01000000.00000035.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_elementtree.pdb source: Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1487065016.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-interlocked-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040068890.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490984740.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Widgets.pdb source: Cerberus.exe, 00000003.00000002.1313316880.00007FFA2CBDA000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\platforms\qwindows.pdb source: Cerberus.exe, 00000003.00000002.1284122627.00007FFA2B504000.00000002.00000001.01000000.00000027.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qwbmp.pdb source: Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1476527410.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\libEGL.pdb source: Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1466506215.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041678538.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494753266.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-string-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042592651.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1496106311.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32api.pdb source: Cerberus.exe, 00000003.00000002.1342478132.00007FFA4C9A3000.00000002.00000001.01000000.0000000C.sdmp
Source: Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488714971.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://aia.startssl.c
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037017106.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1508233060.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://aia.startssl.com/certs/ca.crt0
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037017106.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://aia.startssl.com/certs/sca.code3.crt06
Source: Cerberus.exe, 00000003.00000002.1276064384.000001A9B05C0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2321801362.0000016550200000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://aka.ms/vcpython27
Source: Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1466506215.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredID
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016160330.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
Source: Cerberus.exe, 00000003.00000002.1265538763.000001A9ADD70000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1270723725.000001A9AFF7E000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1083318740.000001A9AFEF3000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2282050833.000001654D980000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://code.activestate.com/recipes/577452-a-memoize-decorator-for-instance-methods/
Source: Cerberus.exe, 00000003.00000002.1266636650.000001A9AF8EB000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2282050833.000001654D980000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://code.activestate.com/recipes/577916/
Source: Cerberus.exe, 00000000.00000003.1036526898.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1484861162.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.mic
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037017106.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.startssl.com/sca-code3.crl0#
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037017106.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1508233060.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.startssl.com/sfsca.crl0f
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1508233060.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016160330.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
Source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016160330.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
Source: Cerberus.exe, 00000000.00000003.1031362637.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1476814482.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016160330.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
Source: Cerberus.exe, 00000003.00000002.1270108941.000001A9AFDF0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2301529867.000001654FA30000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://docs.python.org/library/itertools.html#recipes
Source: Cerberus.exe, 00000003.00000003.1083318740.000001A9AFEF3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://docs.python.org/library/unittest.html
Source: Cerberus.exe, 00000003.00000002.1270108941.000001A9AFDF0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2301529867.000001654FA30000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://foo/bar.tar.gz
Source: Cerberus.exe, 00000003.00000002.1270108941.000001A9AFDF0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2301529867.000001654FA30000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://foo/bar.tgz
Source: Cerberus.exe, 00000003.00000003.1083318740.000001A9AFEF3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://json.org
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0C
Source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022376132.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016160330.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0N
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0O
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037017106.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1508233060.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.startssl.com00
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037017106.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.startssl.com07
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.thawte.com0
Source: Cerberus.exe, 00000003.00000002.1269430972.000001A9AFD30000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1269186347.000001A9AFCB0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2299306839.000001654F950000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2298581635.000001654F910000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://opensource.apple.com/source/CF/CF-744.18/CFBinaryPList.c
Source: Cerberus.exe, 00000013.00000003.1514855202.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://pracrand.sourceforge.net/RNG_engines.txt
Source: Cerberus.exe, 00000003.00000002.1328749112.00007FFA2D528000.00000002.00000001.01000000.00000005.sdmp String found in binary or memory: http://python.org/dev/peps/pep-0263/
Source: Cerberus.exe, 00000003.00000002.1273404472.000001A9B02C0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2303699573.000001654FB00000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://stackoverflow.com/questions/19622133/
Source: Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1487819498.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1508233060.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: Cerberus.exe, 00000013.00000003.1516096587.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-ocsp.ws.s
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: Cerberus.exe, 00000003.00000002.1296443402.00007FFA2C00A000.00000002.00000001.01000000.00000017.sdmp String found in binary or memory: http://www.aiim.org/pdfa/ns/id/
Source: Cerberus.exe, 00000003.00000002.1269000109.000001A9AFC70000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: Cerberus.exe, 00000003.00000002.1296443402.00007FFA2C00A000.00000002.00000001.01000000.00000017.sdmp, Cerberus.exe, 00000015.00000002.2345661381.00007FFA2B920000.00000002.00000001.01000000.0000003F.sdmp String found in binary or memory: http://www.color.org)
Source: Cerberus.exe, 00000003.00000003.1083274553.000001A9B0292000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1084069656.000001A9B01E4000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000003.1554772659.000001654FF36000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.gimp.org/xmp/
Source: Cerberus.exe, 00000013.00000003.1514061349.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.math.sci.hiroshima-u.ac.jp/~m-mat/MT/JUMP/
Source: Cerberus.exe, 00000013.00000003.1496303650.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.microsoft.co
Source: Cerberus.exe, 00000003.00000002.1338582220.00007FFA2E76E000.00000002.00000001.01000000.0000000B.sdmp, Cerberus.exe, 00000013.00000003.1508233060.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1498578781.000001BD8B09C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.openssl.org/V
Source: Cerberus.exe, 00000013.00000003.1514315159.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.pcg-random.org/
Source: Cerberus.exe, 00000013.00000003.1514855202.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.pcg-random.org/posts/random-invertible-mapping-statistics.html
Source: Cerberus.exe, 00000003.00000002.1265367607.000001A9AD8E0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2284456866.000001654DA80000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.python.org/dev/peps/pep-0205/
Source: Cerberus.exe, 00000003.00000002.1264974253.000001A9AD820000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2278424779.000001654D460000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.python.org/download/releases/2.3/mro/.
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037017106.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.startssl.com/0P
Source: Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1487316367.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.startssl.com/policy
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037017106.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038704288.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.startssl.com/policy0
Source: Cerberus.exe, 00000003.00000002.1274080421.000001A9B0380000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1270512734.000001A9AFE70000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2303002647.000001654FAB0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2315239057.000001654FFC0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.python.org/issue44497.
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://codecov.io/github/pyca/cryptography/coverage.svg?branch=master
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://codecov.io/github/pyca/cryptography?branch=master
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://cryptography.io
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://cryptography.io/
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://cryptography.io/en/latest/installation/
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://cryptography.io/en/latest/security/
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://dev.azure.com/pyca/cryptography/_apis/build/status/Azure%20CI?branchName=master
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://dev.azure.com/pyca/cryptography/_build/latest?definitionId=3&branchName=master
Source: Cerberus.exe, 00000013.00000003.1534552445.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1531801819.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1531365367.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1534920108.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1531148201.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1531801819.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1533582497.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1535074118.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1534326957.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1533128154.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1533439270.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1533284965.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1534035468.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1531655687.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1533727302.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1533128154.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1534035468.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1533727302.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1534183275.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1533439270.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1532193344.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://docutils.sourceforge.io
Source: Cerberus.exe, 00000013.00000003.1531010662.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1531010662.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://docutils.sourceforge.io/docs/ref/rst/definitions.html
Source: Cerberus.exe, 00000013.00000003.1531010662.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1531010662.000001BD8B098000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://docutils.sourceforge.io/docs/ref/rst/directives.html#include
Source: Cerberus.exe, 00000003.00000002.1273613660.000001A9B0300000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1275383090.000001A9B0500000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca
Source: Cerberus.exe, 00000003.00000003.1076923830.000001A9AD707000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1265538763.000001A9ADD70000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076905949.000001A9AD70C000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076939713.000001A9AD6FC000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1077181191.000001A9AD6FC000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076998731.000001A9AD6FA000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1264017942.000001A9AD6FA000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2265553492.000001654D2AB000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2282050833.000001654D980000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/Unidata/MetPy/blob/a3424de66a44bf3a92b0dcacf4dff82ad7b86712/src/metpy/plots/wx_sy
Source: Cerberus.exe, 00000003.00000002.1269430972.000001A9AFD30000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1275383090.000001A9B0500000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2299306839.000001654F950000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jaraco/jaraco.functools/issues/5
Source: Cerberus.exe, 00000000.00000003.1039271526.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1039271526.000001ED5D220000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1334025346.00007FFA2E503000.00000002.00000001.01000000.0000000E.sdmp, Cerberus.exe, 00000003.00000002.1342627151.00007FFA4C9B2000.00000002.00000001.01000000.0000000C.sdmp, Cerberus.exe, 00000003.00000002.1342053734.00007FFA4B6E1000.00000002.00000001.01000000.0000000D.sdmp, Cerberus.exe, 00000013.00000003.1489289646.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1518221606.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1520885354.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1521151445.000001BD8B0A0000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1522420961.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1521389099.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1521908297.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1521610524.000001BD8B0A0000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1521151445.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1521610524.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1517847402.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489289646.000001BD8B0A1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/mhammond/pywin32
Source: Cerberus.exe, 00000003.00000002.1269625675.000001A9AFD70000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2300099677.000001654F990000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/platformdirs/platformdirs
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/pyca/cryptography
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/pyca/cryptography/issues
Source: Cerberus.exe, 00000003.00000002.1274080421.000001A9B0380000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1270512734.000001A9AFE70000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2303002647.000001654FAB0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2315239057.000001654FFC0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pypa/packaging
Source: Cerberus.exe, 00000003.00000002.1274080421.000001A9B0380000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2315239057.000001654FFC0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pypa/packaging(P
Source: Cerberus.exe, 00000003.00000002.1270512734.000001A9AFE70000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2303002647.000001654FAB0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pypa/setuptools/issues/1024.
Source: Cerberus.exe, 00000003.00000002.1268164756.000001A9AFB30000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2294324399.000001654F770000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pypa/setuptools/issues/417#issuecomment-392298401
Source: Cerberus.exe, 00000003.00000003.1076923830.000001A9AD707000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076939713.000001A9AD6FC000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1264718786.000001A9AD7A0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2276460949.000001654D3E0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/cpython/blob/3.9/Lib/importlib/_bootstrap_external.py#L679-L688
Source: Cerberus.exe, 00000015.00000002.2282050833.000001654D980000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/abc.py
Source: Cerberus.exe, 00000003.00000003.1076923830.000001A9AD707000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1265538763.000001A9ADD70000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076905949.000001A9AD70C000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076939713.000001A9AD6FC000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1077181191.000001A9AD6FC000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076998731.000001A9AD6FA000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1264017942.000001A9AD6FA000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2265553492.000001654D2AB000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2282050833.000001654D980000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/reader
Source: Cerberus.exe, 00000003.00000002.1274510103.000001A9B0400000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2316586776.0000016550040000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/typing/issues/501.
Source: Cerberus.exe, 00000003.00000003.1076923830.000001A9AD707000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1265538763.000001A9ADD70000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076905949.000001A9AD70C000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076939713.000001A9AD6FC000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1077181191.000001A9AD6FC000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000003.1076998731.000001A9AD6FA000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1264017942.000001A9AD6FA000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2265553492.000001654D2AB000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2282050833.000001654D980000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://img.shields.io/pypi/v/cryptography.svg
Source: Cerberus.exe, 00000003.00000002.1274293298.000001A9B03C0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1269625675.000001A9AFD70000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2315907029.0000016550000000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2300099677.000001654F990000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://importlib-resources.readthedocs.io/en/latest/using.html#migrating-from-legacy
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://mail.python.org/mailman/listinfo/cryptography-dev
Source: Cerberus.exe, 00000003.00000003.1083318740.000001A9AFEF3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://packaging.python.org/en/latest/specifications/declaring-project-metadata/
Source: Cerberus.exe, 00000003.00000002.1276064384.000001A9B05C0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2321801362.0000016550200000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://packaging.python.org/en/latest/specifications/entry-points/
Source: Cerberus.exe, 00000003.00000002.1274293298.000001A9B03C0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1275176470.000001A9B04C0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1274080421.000001A9B0380000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1270512734.000001A9AFE70000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2303002647.000001654FAB0000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2315907029.0000016550000000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2315239057.000001654FFC0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://packaging.python.org/specifications/entry-points/
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://pypi.org/project/cryptography/
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://readthedocs.org/projects/cryptography/badge/?version=latest
Source: Cerberus.exe, 00000003.00000002.1273613660.000001A9B0300000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1275383090.000001A9B0500000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://refspecs.linuxfoundation.org/elf/gabi4
Source: Cerberus.exe, 00000003.00000002.1266636650.000001A9AF8EB000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000003.1548243767.000001654F5D5000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2288470836.000001654F607000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://setuptools.pypa.io/en/latest/pkg_resources.html#basic-resource-access
Source: Cerberus.exe, 00000003.00000002.1274510103.000001A9B0400000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2316586776.0000016550040000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://setuptools.pypa.io/en/latest/userguide/declarative_config.html#opt-2
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://travis-ci.org/pyca/cryptography
Source: Cerberus.exe, 00000013.00000003.1530386896.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://travis-ci.org/pyca/cryptography.svg?branch=master
Source: Cerberus.exe, 00000003.00000002.1269000109.000001A9AFC70000.00000004.00001000.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2315239057.000001654FFC0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://upload.pypi.org/legacy/
Source: Cerberus.exe, 00000013.00000003.1529863282.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.apache.org/licenses/
Source: Cerberus.exe, 00000013.00000003.1529863282.000001BD8B096000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1529863282.000001BD8B0A1000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1530054248.000001BD8B0A1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.apache.org/licenses/LICENSE-2.0
Source: Cerberus.exe, 00000013.00000003.1514315159.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.cs.hmc.edu/tr/hmc-cs-2014-0905.pdf
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031232285.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030834805.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.digicert.com/CPS0
Source: Cerberus.exe, 00000015.00000002.2354645216.00007FFA2CE94000.00000002.00000001.01000000.00000033.sdmp String found in binary or memory: https://www.openssl.org/docs/faq.html
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4185C0 3_2_00007FFA2B4185C0
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4245F0 3_2_00007FFA2B4245F0
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4F4690 3_2_00007FFA2B4F4690
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B488680 3_2_00007FFA2B488680
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B45A6A0 3_2_00007FFA2B45A6A0
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4626A0 3_2_00007FFA2B4626A0
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B440670 3_2_00007FFA2B440670
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B42E510 3_2_00007FFA2B42E510
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B48A510 3_2_00007FFA2B48A510
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4AC530 3_2_00007FFA2B4AC530
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4CE5AB 3_2_00007FFA2B4CE5AB
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B466560 3_2_00007FFA2B466560
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B47FC00 3_2_00007FFA2B47FC00
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B413BD0 3_2_00007FFA2B413BD0
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4E1BF9 3_2_00007FFA2B4E1BF9
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B415C90 3_2_00007FFA2B415C90
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4B5CA0 3_2_00007FFA2B4B5CA0
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B45BC60 3_2_00007FFA2B45BC60
Source: python3.dll.0.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: pyexpat.pyd.0.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: select.pyd.0.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: Number of sections : 19 > 10
Source: api-ms-win-core-interlocked-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-processenvironment-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-util-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-console-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-process-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-synch-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-timezone-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-file-l2-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-debug-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-string-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-localization-l1-2-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-profile-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-datetime-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-math-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-locale-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-time-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-namedpipe-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-file-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-file-l1-2-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-sysinfo-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-libraryloader-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: python3.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-heap-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-environment-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-stdio-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-processthreads-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-errorhandling-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-handle-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-synch-l1-2-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-processthreads-l1-1-1.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-utility-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-filesystem-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-multibyte-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-rtlsupport-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-conio-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-heap-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-convert-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-runtime-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-string-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-core-memory-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: Cerberus.exe, 00000000.00000003.1040830660.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039846078.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_contextvars.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040148966.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1036643564.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_asyncio.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041137335.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1037108796.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_ctypes.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1042388903.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqtuiotouchplugin.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040222688.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_bz2.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041869110.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041302528.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039988364.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqicns.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwbmp.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1013129011.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Gui.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1042592651.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqxdgdesktopportal.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041397947.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041678538.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1042763134.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1022731007.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibGLESv2.dll4 vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1042681893.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040606049.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039271526.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_win32sysloader.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1038932334.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_sqlite3.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040899040.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039764961.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1038510446.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_multiprocessing.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_queue.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039597661.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039505205.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1030646492.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqjpeg.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1031804183.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqminimal.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040752593.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039271526.000001ED5D220000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_win32sysloader.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1042499310.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1010418304.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp140_1.dllT vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1019037281.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5WebSockets.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1033012436.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwindows.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_lzma.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040459680.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1016928250.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5QmlModels.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_overlapped.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039351663.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqsvg.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1032360974.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqoffscreen.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1018869722.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Svg.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040310667.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040978083.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1036526898.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140.dll^ vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1037383987.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_distutils_findvs.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1020697132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140_1.dllT vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_distutils_findvs.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039423592.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqtga.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqico.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1037245026.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_decimal.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqtiff.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_elementtree.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040068890.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqgif.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibEGL.dll. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040684530.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040533959.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1016160330.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Qml.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039107009.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_ssl.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1012349434.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5DBus.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041062292.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039684455.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_hashlib.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1038801185.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_socket.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041223693.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1030266270.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqsvgicon.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1033520878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwindowsvistastyle.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041578087.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1038704288.000001ED5D21F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_queue.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1011049470.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Core.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041474837.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041785502.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1032662821.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwebgl.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1031362637.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwebp.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1015522771.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Network.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1039914529.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_multiprocessing.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1040382883.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1010211035.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp140.dllT vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1041969980.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000000.00000003.1042067758.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe Binary or memory string: OriginalFilename vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1283077392.00007FFA2B402000.00000002.00000001.01000000.00000028.sdmp Binary or memory string: OriginalFilenameqwindowsvistastyle.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1346036647.00007FFA50DF6000.00000002.00000001.01000000.00000012.sdmp Binary or memory string: OriginalFilename_queue.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1346705754.00007FFA51155000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: OriginalFilename_bz2.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1340380577.00007FFA4B42E000.00000002.00000001.01000000.0000000F.sdmp Binary or memory string: OriginalFilenamepyexpat.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1284662389.00007FFA2B56B000.00000002.00000001.01000000.00000027.sdmp Binary or memory string: OriginalFilenameqwindows.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1347256200.00007FFA5333F000.00000002.00000001.01000000.00000007.sdmp Binary or memory string: OriginalFilename_ctypes.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1347525738.00007FFA53363000.00000002.00000001.01000000.00000006.sdmp Binary or memory string: OriginalFilenamevcruntime140.dll^ vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1346182471.00007FFA50E06000.00000002.00000001.01000000.00000011.sdmp Binary or memory string: OriginalFilenameselect.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1334025346.00007FFA2E503000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: OriginalFilenamepythoncom37.dll0 vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1346888198.00007FFA52FDA000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: OriginalFilename_hashlib.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1338582220.00007FFA2E76E000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: OriginalFilenamelibcrypto-1_1-x64.dllH vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1342627151.00007FFA4C9B2000.00000002.00000001.01000000.0000000C.sdmp Binary or memory string: OriginalFilenamewin32api.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1342053734.00007FFA4B6E1000.00000002.00000001.01000000.0000000D.sdmp Binary or memory string: OriginalFilenamepywintypes37.dll0 vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1316550773.00007FFA2CDA3000.00000002.00000001.01000000.00000015.sdmp Binary or memory string: OriginalFilenameQt5Widgets.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1345799328.00007FFA50512000.00000002.00000001.01000000.00000014.sdmp Binary or memory string: OriginalFilenamepython3.dll. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1346454232.00007FFA51132000.00000002.00000001.01000000.00000010.sdmp Binary or memory string: OriginalFilename_socket.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1332458788.00007FFA2D685000.00000002.00000001.01000000.00000005.sdmp Binary or memory string: OriginalFilenamepython37.dll. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1345640745.00007FFA503D2000.00000002.00000001.01000000.00000004.sdmp Binary or memory string: OriginalFilenameucrtbase.dllj% vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1343612570.00007FFA502CD000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: OriginalFilename_lzma.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1299785233.00007FFA2C289000.00000002.00000001.01000000.00000017.sdmp Binary or memory string: OriginalFilenameQt5Gui.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000003.00000002.1307736603.00007FFA2C820000.00000002.00000001.01000000.00000016.sdmp Binary or memory string: OriginalFilenameQt5Core.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1486282814.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_ctypes.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1451582472.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp140.dllT vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1494393244.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_queue.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1474747129.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqico.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1489974962.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1467020819.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibGLESv2.dll4 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1496303650.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1490811944.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1519334597.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesqlite3.dll0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1476135310.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqtiff.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1489289646.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_win32sysloader.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1494753266.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameselect.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1461674900.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Svg.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1518221606.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamepywintypes37.dll0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1477837490.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqoffscreen.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1475756466.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqtga.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1495512088.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1475011169.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqjpeg.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1452795703.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Core.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1475425345.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqsvg.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1491482836.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1473593522.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqtuiotouchplugin.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1479519653.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqxdgdesktopportal.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1520885354.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamewin32api.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1521151445.000001BD8B0A0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamewin32event.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1459934124.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5QmlModels.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1493753211.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1466506215.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1466506215.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibEGL.dll. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1508233060.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibssl-1_1-x64.dllH vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1522420961.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamewin32wnet.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1494087186.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1523279854.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp140.dll^ vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1490648135.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1518945327.000001BD8B0A0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameselect.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1485210122.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_asyncio.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1476527410.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwbmp.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1486575043.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_decimal.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1521389099.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamewin32pdh.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1474496726.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqicns.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1491828013.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1496106311.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1488253530.000001BD8B0A0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_queue.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1473876495.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqsvgicon.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1493914313.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1496482072.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1484861162.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140.dll^ vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1516386598.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamepython3.dll. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1491658121.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1491327022.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1521908297.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamewin32ui.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1519955215.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameucrtbase.dllj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1493074778.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1488032558.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_overlapped.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1487819498.000001BD8B0A0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_multiprocessing.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1516096587.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamepyexpat.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1491997872.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1495915120.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1487316367.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_hashlib.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1521610524.000001BD8B0A0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamewin32trace.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1452032998.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp140_1.dllT vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1455805688.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Gui.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1521151445.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamewin32event.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1495112300.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1488714971.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_sqlite3.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1477324352.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqminimal.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1478328144.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwebgl.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1487065016.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_elementtree.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1487819498.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_multiprocessing.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1520457149.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameunicodedata.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1490984740.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1458958795.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Qml.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1495315228.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1457399661.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Network.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1474216247.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqgif.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1489805185.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1486077976.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_contextvars.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1492561174.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1485461386.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_bz2.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1490325210.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1492217227.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1521610524.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamewin32trace.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1493250955.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1479831425.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwindowsvistastyle.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1488480762.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_socket.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1486840418.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_distutils_findvs.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1454815680.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5DBus.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1464910511.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140_1.dllT vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1517847402.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamepythoncom37.dll0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1498578781.000001BD8B09C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibcrypto-1_1-x64.dllH vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1490151420.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1476814482.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwebp.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1492735859.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1486840418.000001BD8B0A0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_distutils_findvs.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1493421050.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1489020402.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_ssl.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1495734423.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1462114396.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5WebSockets.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1491149058.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1494936977.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1494558175.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1492902278.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1490487800.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1493585475.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1478881471.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameqwindows.dll( vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1487538290.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_lzma.pyd. vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1489289646.000001BD8B0A1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_win32sysloader.pyd0 vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1489453698.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: Cerberus.exe, 00000013.00000003.1489629042.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameapisetstubj% vs Cerberus.exe
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: libcrypto-1_1-x64.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: pywintypes37.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: qt5widgets.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: qt5gui.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: python3.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: scrrun.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: libcrypto-1_1-x64.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: pywintypes37.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: qt5widgets.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: qt5gui.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: python3.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: scrrun.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Section loaded: umpdc.dll Jump to behavior
Source: Qt5Core.dll.0.dr Static PE information: Section: .qtmimed ZLIB complexity 0.997458770800317
Source: classification engine Classification label: clean7.winEXE@8/564@0/1
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\Desktop\logs Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:504:120:WilError_03
Source: C:\Users\user\Desktop\Cerberus.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6936:120:WilError_03
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402 Jump to behavior
Source: Cerberus.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Cerberus.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: Cerberus.exe String found in binary or memory: <!--StartFragment-->
Source: Cerberus.exe String found in binary or memory: did not find expected <stream-start>
Source: Cerberus.exe String found in binary or memory: expected STREAM-START
Source: Cerberus.exe String found in binary or memory: expected SCALAR, SEQUENCE-START, MAPPING-START, or ALIAS
Source: Cerberus.exe String found in binary or memory: expected DOCUMENT-START or STREAM-END
Source: Cerberus.exe String found in binary or memory: Peer-Address
Source: C:\Users\user\Desktop\Cerberus.exe File read: C:\Users\user\Desktop\Cerberus.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Cerberus.exe "C:\Users\user\Desktop\Cerberus.exe"
Source: C:\Users\user\Desktop\Cerberus.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\Cerberus.exe Process created: C:\Users\user\Desktop\Cerberus.exe "C:\Users\user\Desktop\Cerberus.exe"
Source: unknown Process created: C:\Users\user\Desktop\Cerberus.exe "C:\Users\user\Desktop\Cerberus.exe"
Source: C:\Users\user\Desktop\Cerberus.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\Cerberus.exe Process created: C:\Users\user\Desktop\Cerberus.exe "C:\Users\user\Desktop\Cerberus.exe"
Source: C:\Users\user\Desktop\Cerberus.exe Process created: C:\Users\user\Desktop\Cerberus.exe "C:\Users\user\Desktop\Cerberus.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process created: C:\Users\user\Desktop\Cerberus.exe "C:\Users\user\Desktop\Cerberus.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File opened: C:\Users\user\Desktop\pyvenv.cfg Jump to behavior
Source: Cerberus.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: Cerberus.exe Static file information: File size 65183922 > 1048576
Source: Cerberus.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: Cerberus.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: Cerberus.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: Cerberus.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Cerberus.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: Cerberus.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: Cerberus.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Cerberus.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: api-ms-win-crt-locale-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041785502.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494936977.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\pythoncom.pdb source: Cerberus.exe, 00000003.00000002.1333435908.00007FFA2E4AE000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\pywintypes.pdb** source: Cerberus.exe, 00000003.00000002.1341889125.00007FFA4B6D0000.00000002.00000001.01000000.0000000D.sdmp, Cerberus.exe, 00000015.00000002.2359656832.00007FFA33065000.00000002.00000001.01000000.00000035.sdmp
Source: Binary string: api-ms-win-crt-runtime-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042388903.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495734423.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\imageformats\qsvg.pdb source: Cerberus.exe, 00000000.00000003.1030834805.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1475425345.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\iconengines\qsvgicon.pdb source: Cerberus.exe, 00000000.00000003.1030266270.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1473876495.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\generic\qtuiotouchplugin.pdb source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1473593522.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-file-l1-2-0.pdb source: Cerberus.exe, 00000000.00000003.1039764961.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490325210.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_hashlib.pdb source: Cerberus.exe, 00000000.00000003.1037614633.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1346818337.00007FFA52FD5000.00000002.00000001.01000000.0000000A.sdmp, Cerberus.exe, 00000013.00000003.1487316367.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360902164.00007FFA4B4E5000.00000002.00000001.01000000.00000032.sdmp
Source: Binary string: ucrtbase.pdb source: Cerberus.exe, 00000003.00000002.1345128415.00007FFA50395000.00000002.00000001.01000000.00000004.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1474747129.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-memory-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040310667.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491482836.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-debug-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039505205.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489805185.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32trace.pdb source: Cerberus.exe, 00000013.00000003.1521610524.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_overlapped.pdb source: Cerberus.exe, 00000000.00000003.1038609620.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1488032558.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041062292.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493421050.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-filesystem-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041578087.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494558175.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_distutils_findvs.pdb source: Cerberus.exe, 00000000.00000003.1037383987.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486840418.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build\cpython37\externals\openssl-1.1.0h\tmp64dll\libcrypto-1_1-x64.pdb source: Cerberus.exe, 00000003.00000002.1337113943.00007FFA2E6FA000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\select.pdb source: Cerberus.exe, 00000003.00000002.1346128348.00007FFA50E03000.00000002.00000001.01000000.00000011.sdmp, Cerberus.exe, 00000013.00000003.1518945327.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360356467.00007FFA4AA53000.00000002.00000001.01000000.00000039.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_contextvars.pdb source: Cerberus.exe, 00000000.00000003.1037017106.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1486077976.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32api.pdb source: Cerberus.exe, 00000003.00000002.1342478132.00007FFA4C9A3000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042499310.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495915120.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: Cerberus.exe, 00000000.00000003.1020697132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1464910511.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-heap-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039988364.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490811944.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-util-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041223693.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493753211.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-synch-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040899040.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493074778.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041474837.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494393244.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\styles\qwindowsvistastyle.pdb%% source: Cerberus.exe, 00000003.00000002.1282991340.00007FFA2B3F7000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\styles\qwindowsvistastyle.pdb source: Cerberus.exe, 00000003.00000002.1282991340.00007FFA2B3F7000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: api-ms-win-core-errorhandling-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039597661.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489974962.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vcruntime140.amd64.pdbGCTL source: Cerberus.exe, 00000000.00000003.1036526898.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1347450263.00007FFA5335E000.00000002.00000001.01000000.00000006.sdmp, Cerberus.exe, 00000013.00000003.1484861162.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360787359.00007FFA4B42E000.00000002.00000001.01000000.0000002E.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: Cerberus.exe, 00000000.00000003.1030537291.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1474747129.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_multiprocessing.pdb source: Cerberus.exe, 00000000.00000003.1038510446.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1487819498.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-processthreads-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040533959.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491997872.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-console-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039351663.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489453698.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_ctypes.pdb source: Cerberus.exe, 00000003.00000002.1347129083.00007FFA53334000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: api-ms-win-core-file-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039684455.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490151420.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\generic\qtuiotouchplugin.pdb source: Cerberus.exe, 00000000.00000003.1030141154.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1473593522.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-convert-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041397947.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494087186.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdbT source: Cerberus.exe, 00000003.00000002.1304279470.00007FFA2C746000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Gui.pdb source: Cerberus.exe, 00000003.00000002.1296443402.00007FFA2C00A000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\python37.pdb source: Cerberus.exe, 00000003.00000002.1328749112.00007FFA2D528000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\_win32sysloader.pdb source: Cerberus.exe, 00000000.00000003.1039271526.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489289646.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-profile-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040684530.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1492561174.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ucrtbase.pdbUGP source: Cerberus.exe, 00000003.00000002.1345128415.00007FFA50395000.00000002.00000001.01000000.00000004.sdmp
Source: Binary string: C:\build\cpython37\externals\openssl-1.1.0h\tmp64dll\libcrypto-1_1-x64.pdbo source: Cerberus.exe, 00000003.00000002.1337113943.00007FFA2E6FA000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: vcruntime140.amd64.pdb source: Cerberus.exe, 00000000.00000003.1036526898.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1347450263.00007FFA5335E000.00000002.00000001.01000000.00000006.sdmp, Cerberus.exe, 00000013.00000003.1484861162.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360787359.00007FFA4B42E000.00000002.00000001.01000000.0000002E.sdmp
Source: Binary string: api-ms-win-crt-time-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042681893.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1496303650.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_queue.pdb source: Cerberus.exe, 00000000.00000003.1038704288.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1345978475.00007FFA50DF3000.00000002.00000001.01000000.00000012.sdmp, Cerberus.exe, 00000013.00000003.1488253530.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2359888076.00007FFA33263000.00000002.00000001.01000000.0000003A.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdbBB source: Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1476135310.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\platformthemes\qxdgdesktopportal.pdb source: Cerberus.exe, 00000000.00000003.1033392234.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1479519653.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-handle-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039914529.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490648135.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: Cerberus.exe, 00000000.00000003.1010418304.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1452032998.000001BD8B092000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_lzma.pdbMM source: Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1343458423.00007FFA502C4000.00000002.00000001.01000000.00000009.sdmp, Cerberus.exe, 00000013.00000003.1487538290.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2355865494.00007FFA2CF68000.00000002.00000001.01000000.00000031.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdb source: Cerberus.exe, 00000003.00000002.1304279470.00007FFA2C746000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdb source: Cerberus.exe, 00000000.00000003.1031056556.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1476135310.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-synch-l1-2-0.pdb source: Cerberus.exe, 00000000.00000003.1040978083.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493250955.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qgif.pdb source: Cerberus.exe, 00000000.00000003.1030361506.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1474216247.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\pythoncom.pdb}},GCTL source: Cerberus.exe, 00000003.00000002.1333435908.00007FFA2E4AE000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_bz2.pdb source: Cerberus.exe, 00000000.00000003.1036752878.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1346639585.00007FFA5114F000.00000002.00000001.01000000.00000008.sdmp, Cerberus.exe, 00000013.00000003.1485461386.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2360667127.00007FFA4B40F000.00000002.00000001.01000000.00000030.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32pdh.pdb source: Cerberus.exe, 00000013.00000003.1521389099.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-processenvironment-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040459680.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491828013.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-datetime-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039423592.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1489629042.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_lzma.pdb source: Cerberus.exe, 00000000.00000003.1037713626.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000003.00000002.1343458423.00007FFA502C4000.00000002.00000001.01000000.00000009.sdmp, Cerberus.exe, 00000013.00000003.1487538290.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2355865494.00007FFA2CF68000.00000002.00000001.01000000.00000031.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_socket.pdb source: Cerberus.exe, 00000003.00000002.1346315682.00007FFA51129000.00000002.00000001.01000000.00000010.sdmp, Cerberus.exe, 00000015.00000002.2360164022.00007FFA4AA19000.00000002.00000001.01000000.00000038.sdmp
Source: Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041302528.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493914313.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtga.pdb source: Cerberus.exe, 00000000.00000003.1030929977.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1475756466.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32event.pdb source: Cerberus.exe, 00000013.00000003.1521151445.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-localization-l1-2-0.pdb source: Cerberus.exe, 00000000.00000003.1040222688.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491327022.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-math-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041869110.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495112300.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: Cerberus.exe, 00000000.00000003.1040606049.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1492217227.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qicns.pdb source: Cerberus.exe, 00000000.00000003.1030446721.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1474496726.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\pyexpat.pdb source: Cerberus.exe, 00000003.00000002.1340267049.00007FFA4B423000.00000002.00000001.01000000.0000000F.sdmp, Cerberus.exe, 00000015.00000002.2353918702.00007FFA2CBE3000.00000002.00000001.01000000.00000037.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32wnet.pdb source: Cerberus.exe, 00000013.00000003.1522420961.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040382883.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491658121.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-multibyte-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041969980.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495315228.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-utility-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042763134.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1496482072.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-rtlsupport-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040752593.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1492735859.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-timezone-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041137335.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1493585475.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-string-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040830660.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1492902278.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-file-l2-1-0.pdb source: Cerberus.exe, 00000000.00000003.1039846078.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490487800.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-process-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042067758.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1495512088.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-libraryloader-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040148966.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1491149058.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\python3.pdb source: Cerberus.exe, 00000003.00000002.1345799328.00007FFA50512000.00000002.00000001.01000000.00000014.sdmp, Cerberus.exe, 00000013.00000003.1516386598.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\pywintypes.pdb source: Cerberus.exe, 00000003.00000002.1341889125.00007FFA4B6D0000.00000002.00000001.01000000.0000000D.sdmp, Cerberus.exe, 00000015.00000002.2359656832.00007FFA33065000.00000002.00000001.01000000.00000035.sdmp
Source: Binary string: C:\_work\4\s\PCbuild\amd64\_elementtree.pdb source: Cerberus.exe, 00000000.00000003.1037478812.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1487065016.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-core-interlocked-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1040068890.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1490984740.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Widgets.pdb source: Cerberus.exe, 00000003.00000002.1313316880.00007FFA2CBDA000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\platforms\qwindows.pdb source: Cerberus.exe, 00000003.00000002.1284122627.00007FFA2B504000.00000002.00000001.01000000.00000027.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qwbmp.pdb source: Cerberus.exe, 00000000.00000003.1031232285.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1476527410.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\libEGL.pdb source: Cerberus.exe, 00000000.00000003.1022376132.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1466506215.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1041678538.000001ED5D216000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1494753266.000001BD8B097000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: api-ms-win-crt-string-l1-1-0.pdb source: Cerberus.exe, 00000000.00000003.1042592651.000001ED5D212000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000013.00000003.1496106311.000001BD8B093000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-3.7\Release\win32api.pdb source: Cerberus.exe, 00000003.00000002.1342478132.00007FFA4C9A3000.00000002.00000001.01000000.0000000C.sdmp
Source: Cerberus.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: Cerberus.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: Cerberus.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: Cerberus.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: Cerberus.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: api-ms-win-core-console-l1-1-0.dll.0.dr Static PE information: 0xF9CDD9FE [Mon Oct 23 03:31:10 2102 UTC]
Source: Cerberus.exe Static PE information: section name: _RDATA
Source: MSVCP140.dll.0.dr Static PE information: section name: .didat
Source: Qt5Core.dll.0.dr Static PE information: section name: .qtmimed
Source: libcrypto-1_1-x64.dll.0.dr Static PE information: section name: .00cfg
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: .xdata
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: /4
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: /19
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: /31
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: /45
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: /57
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: /70
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: /81
Source: libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll.0.dr Static PE information: section name: /92
Source: libssl-1_1-x64.dll.0.dr Static PE information: section name: .00cfg
Source: mfc140u.dll.0.dr Static PE information: section name: .didat
Source: opengl32sw.dll.0.dr Static PE information: section name: _RDATA
Source: qtuiotouchplugin.dll.0.dr Static PE information: section name: .qtmetad
Source: qsvgicon.dll.0.dr Static PE information: section name: .qtmetad
Source: qgif.dll.0.dr Static PE information: section name: .qtmetad
Source: qicns.dll.0.dr Static PE information: section name: .qtmetad
Source: qico.dll.0.dr Static PE information: section name: .qtmetad
Source: qjpeg.dll.0.dr Static PE information: section name: .qtmetad
Source: qsvg.dll.0.dr Static PE information: section name: .qtmetad
Source: qtga.dll.0.dr Static PE information: section name: .qtmetad
Source: qtiff.dll.0.dr Static PE information: section name: .qtmetad
Source: qwbmp.dll.0.dr Static PE information: section name: .qtmetad
Source: qwebp.dll.0.dr Static PE information: section name: .qtmetad
Source: qminimal.dll.0.dr Static PE information: section name: .qtmetad
Source: qoffscreen.dll.0.dr Static PE information: section name: .qtmetad
Source: qwebgl.dll.0.dr Static PE information: section name: .qtmetad
Source: qwindows.dll.0.dr Static PE information: section name: .qtmetad
Source: qxdgdesktopportal.dll.0.dr Static PE information: section name: .qtmetad
Source: qwindowsvistastyle.dll.0.dr Static PE information: section name: .qtmetad
Source: _constant_time.cp37-win_amd64.pyd.0.dr Static PE information: section name: _RDATA
Source: _openssl.cp37-win_amd64.pyd.0.dr Static PE information: section name: _RDATA
Source: _padding.cp37-win_amd64.pyd.0.dr Static PE information: section name: _RDATA
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Gui.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\VCRUNTIME140_1.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_elementtree.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\MSVCP140.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\win32trace.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-localization-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\constants.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\win32pdh.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\libglesv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\mtrand.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qwebgl.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_contextvars.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\python37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qwebp.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qsvg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\wrapt\_wrappers.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\iconengines\qsvgicon.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-datetime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\win32api.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qtga.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_imaging.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\libssl-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-util-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-processenvironment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_socket.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qtiff.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\core\_multiarray_tests.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Qml.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Svg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\libcrypto-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-math-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-interlocked-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\mfc140u.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-environment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\python3.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\yaml\_yaml.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\bit_generator.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-memory-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_hashlib.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_asyncio.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-profile-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\win32event.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\select.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-debug-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtWidgets.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-utility-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_webp.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\unicodedata.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5DBus.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-sysinfo-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-interlocked-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-stdio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5WebSockets.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-errorhandling-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography\hazmat\bindings\_constant_time.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\generic\qtuiotouchplugin.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\iconengines\qsvgicon.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_mt19937.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\constants.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qwindows.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32\pythoncom37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\libzmq.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\linalg\lapack_lite.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5WebSockets.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\reportlab\graphics\_renderPM.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-synch-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Svg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\yaml\_yaml.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-convert-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_common.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-multibyte-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_imagingcms.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-environment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\fft\_pocketfft_internal.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\fft\_pocketfft_internal.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qjpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_elementtree.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\MSVCP140.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\win32ui.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_philox.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography\hazmat\bindings\_openssl.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-sysinfo-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-conio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Qml.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_queue.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platformthemes\qxdgdesktopportal.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\cryptography\hazmat\bindings\_openssl.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\linalg\_umath_linalg.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qwebp.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-filesystem-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-time-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-multibyte-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_ctypes.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_imaging.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\QtCore.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_contextvars.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\ucrtbase.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\win32ui.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-processthreads-l1-1-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-stdio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\select.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5QmlModels.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32\pywintypes37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\context.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_multiprocessing.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-process-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-synch-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_bz2.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\wrapt\_wrappers.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-localization-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_proxy_steerable.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\win32pdh.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\win32event.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-runtime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\win32trace.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\core\_multiarray_umath.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-file-l2-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-namedpipe-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_generator.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qoffscreen.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\libcrypto-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-processthreads-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\cryptography\hazmat\bindings\_padding.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platforms\qoffscreen.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platformthemes\qxdgdesktopportal.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-handle-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_bounded_integers.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\libssl-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_win32sysloader.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_decimal.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-synch-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_imagingtk.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-file-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-math-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5DBus.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_ssl.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_ctypes.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qicns.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\mtrand.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qico.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_lzma.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platforms\qwebgl.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-synch-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-filesystem-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-utility-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\linalg\lapack_lite.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-process-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtGui.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\pywin32_system32\pywintypes37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\_proxy_steerable.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_bz2.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-processenvironment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qminimal.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_lzma.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\libzmq.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qgif.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_win32sysloader.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_sqlite3.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-errorhandling-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_philox.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-datetime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-processthreads-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_sfc64.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_hashlib.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\styles\qwindowsvistastyle.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_common.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\styles\qwindowsvistastyle.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platforms\qwindows.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_bounded_integers.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_version.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\message.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_device.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtCore.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-file-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Network.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_mt19937.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Quick.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\MSVCP140.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-libraryloader-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\psutil\_psutil_windows.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\pywin32_system32\pythoncom37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\opengl32sw.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\python3.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\MSVCP140.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\win32wnet.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\generic\qtuiotouchplugin.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5QmlModels.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Gui.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\_version.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-processthreads-l1-1-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\VCRUNTIME140.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\VCRUNTIME140.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\mfc140u.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-time-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\d3dcompiler_47.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-locale-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography\hazmat\bindings\_padding.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_distutils_findvs.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\opengl32sw.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\sip.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_imagingft.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_cffi_backend.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_generator.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\pyexpat.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Widgets.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_queue.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\unicodedata.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\win32api.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_imagingft.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_socket.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-locale-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\context.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_sfc64.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platforms\qminimal.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qwbmp.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qico.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-console-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\sip.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_decimal.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_poll.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_webp.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\python37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\libglesv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qsvg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-file-l2-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\socket.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\QtWidgets.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-profile-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qtga.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\libegl.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qicns.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-file-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\_poll.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qtiff.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\VCRUNTIME140_1.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\bit_generator.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-timezone-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-debug-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\socket.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-rtlsupport-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Widgets.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-handle-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\MSVCP140_1.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_sqlite3.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-util-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qwbmp.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-memory-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\error.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_imagingtk.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\pyexpat.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\utils.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_imagingcms.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_overlapped.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\reportlab\graphics\_renderPM.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\cryptography\hazmat\bindings\_constant_time.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_pcg64.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-timezone-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\psutil\_psutil_windows.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-rtlsupport-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-convert-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\error.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\win32wnet.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qgif.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_pcg64.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-namedpipe-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\core\_multiarray_tests.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_cffi_backend.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\linalg\_umath_linalg.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-libraryloader-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_asyncio.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_ssl.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\utils.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\_multiprocessing.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\d3dcompiler_47.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Network.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\message.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\MSVCP140_1.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qjpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\libegl.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_distutils_findvs.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Quick.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\_overlapped.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-file-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\core\_multiarray_umath.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\ucrtbase.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-conio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\_device.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\QtGui.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-runtime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-console-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst\include\README.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes\README.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI7402\wheel-0.38.4.dist-info\LICENSE.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\docutils\parsers\rst\include\README.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\docutils\writers\s5_html\themes\README.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe File created: C:\Users\user\AppData\Local\Temp\_MEI69282\wheel-0.38.4.dist-info\LICENSE.txt Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2B4204F0 ??0?$QVector@VQPointF@@@@QEAA@XZ,??4QString@@QEAAAEAV0@AEBV0@@Z,??1QString@@QEAA@XZ,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?Windows8@QOperatingSystemVersion@@2V1@B,?current@QOperatingSystemVersion@@SA?AV1@XZ,?compare@QOperatingSystemVersion@@CAHAEBV1@0@Z,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,??0QOperatingSystemVersion@@QEAA@W4OSType@0@HHH@Z,?current@QOperatingSystemVersion@@SA?AV1@XZ,?compare@QOperatingSystemVersion@@CAHAEBV1@0@Z,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,?utf16@QString@@QEBAPEBGXZ,?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z,GetProcAddress,??1QString@@QEAA@XZ, 3_2_00007FFA2B4204F0
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_elementtree.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-localization-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\constants.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\win32trace.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\win32pdh.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\libglesv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\mtrand.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qwebgl.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_contextvars.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\python37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qwebp.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qsvg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\iconengines\qsvgicon.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\wrapt\_wrappers.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-datetime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\win32api.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qtga.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_imaging.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\libssl-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-util-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-processenvironment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_socket.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qtiff.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\core\_multiarray_tests.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Qml.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Svg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-math-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-interlocked-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\mfc140u.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-environment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\yaml\_yaml.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\bit_generator.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_hashlib.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-memory-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_asyncio.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-profile-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\win32event.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\select.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-debug-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtWidgets.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-utility-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_webp.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\unicodedata.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5DBus.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-sysinfo-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-interlocked-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-stdio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5WebSockets.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-errorhandling-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography\hazmat\bindings\_constant_time.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\generic\qtuiotouchplugin.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\iconengines\qsvgicon.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_mt19937.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\constants.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qwindows.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32\pythoncom37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\libzmq.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\linalg\lapack_lite.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5WebSockets.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\reportlab\graphics\_renderPM.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-synch-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Svg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\yaml\_yaml.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-convert-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_imagingcms.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-multibyte-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_common.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-environment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\fft\_pocketfft_internal.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\fft\_pocketfft_internal.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qjpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_elementtree.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\win32ui.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_philox.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography\hazmat\bindings\_openssl.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-conio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-sysinfo-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Qml.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_queue.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platformthemes\qxdgdesktopportal.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\cryptography\hazmat\bindings\_openssl.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\linalg\_umath_linalg.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qwebp.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-filesystem-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-time-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-multibyte-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_imaging.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_ctypes.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\QtCore.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_contextvars.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\win32ui.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-processthreads-l1-1-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-stdio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5QmlModels.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\select.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-process-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_multiprocessing.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\context.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-synch-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_bz2.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\wrapt\_wrappers.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-localization-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_proxy_steerable.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\win32pdh.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\win32event.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-runtime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\win32trace.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\core\_multiarray_umath.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-namedpipe-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-file-l2-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_generator.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qoffscreen.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-processthreads-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\cryptography\hazmat\bindings\_padding.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platforms\qoffscreen.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-handle-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platformthemes\qxdgdesktopportal.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_bounded_integers.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_win32sysloader.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\libssl-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_decimal.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_imagingtk.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-synch-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-file-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-math-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_ssl.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5DBus.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_ctypes.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qicns.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\mtrand.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platforms\qwebgl.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qico.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_lzma.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-synch-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-filesystem-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-utility-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\linalg\lapack_lite.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-process-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtGui.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\_proxy_steerable.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_bz2.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-processenvironment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qminimal.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_lzma.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\libzmq.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_win32sysloader.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qgif.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_sqlite3.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-errorhandling-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_philox.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-datetime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-processthreads-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_sfc64.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_hashlib.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\styles\qwindowsvistastyle.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_common.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\styles\qwindowsvistastyle.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platforms\qwindows.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_bounded_integers.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_version.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\message.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_device.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtCore.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-file-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Network.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Quick.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_mt19937.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-libraryloader-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\pywin32_system32\pythoncom37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\psutil\_psutil_windows.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\opengl32sw.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\win32wnet.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\generic\qtuiotouchplugin.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5QmlModels.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-processthreads-l1-1-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\_version.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\mfc140u.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-locale-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-time-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\d3dcompiler_47.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography\hazmat\bindings\_padding.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_distutils_findvs.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\opengl32sw.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\sip.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_imagingft.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_cffi_backend.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_generator.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\pyexpat.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_queue.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PIL\_imagingft.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\unicodedata.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\win32api.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_socket.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-locale-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\context.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_sfc64.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\platforms\qminimal.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qwbmp.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qico.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-console-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\sip.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_decimal.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_poll.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_webp.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\python37.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\libglesv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qsvg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\socket.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\QtWidgets.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-file-l2-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-profile-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qtga.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\libegl.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-file-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qicns.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\_poll.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qtiff.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\libopenblas.XWYDX2IKJW2NMTWSFYNGFUWKQU3LYTCZ.gfortran-win_amd64.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-timezone-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\bit_generator.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-debug-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\socket.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-rtlsupport-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-handle-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-util-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_sqlite3.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qwbmp.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-memory-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\error.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\pyexpat.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_imagingtk.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\utils.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL\_imagingcms.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_overlapped.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\reportlab\graphics\_renderPM.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\cryptography\hazmat\bindings\_constant_time.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\random\_pcg64.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-timezone-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\psutil\_psutil_windows.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-rtlsupport-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-crt-convert-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\error.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\win32wnet.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\plugins\imageformats\qgif.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\random\_pcg64.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-namedpipe-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\core\_multiarray_tests.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-libraryloader-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_cffi_backend.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\numpy\linalg\_umath_linalg.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_asyncio.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_ssl.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\utils.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\_multiprocessing.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\d3dcompiler_47.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\Qt5Network.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\message.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_distutils_findvs.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats\qjpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\Qt5\bin\libegl.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Quick.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-core-file-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\_overlapped.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy\core\_multiarray_umath.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-conio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\zmq\backend\cython\_device.cp37-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\PyQt5\QtGui.pyd Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI69282\api-ms-win-crt-runtime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\Cerberus.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI7402\api-ms-win-core-console-l1-1-0.dll Jump to dropped file
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: Cerberus.exe, 00000015.00000002.2345259529.00007FFA2B42B000.00000002.00000001.01000000.00000044.sdmp Binary or memory string: ETERMECONNREFUSEDEVENT_CLOSEDPLAIN_USERNAMESTREAM_NOTIFYCURVE_SECRETKEYCURVE_SERVERIDENTITYIMMEDIATESRCFDTHREAD_PRIORITYNOBLOCKEVENT_DISCONNECTEDSNDTIMEORADIOPROTOCOL_ERROR_ZMTP_MALFORMED_COMMAND_WELCOMEPROTOCOL_ERROR_ZAP_INVALID_METADATAEVENT_MONITOR_STOPPEDGSSAPI_NT_HOSTBASEDVERSIONEVENT_CONNECTEDPROTOCOL_ERROR_ZAP_MALFORMED_REPLYREQ_RELAXEDMSG_T_SIZESTREAMEREVENT_ALLEAFNOSUPPORTEVENT_HANDSHAKE_FAILED_AUTHECONNABORTEDVERSION_MINORPLAIN_PASSWORDRCVMORETYPETHREAD_AFFINITY_CPU_ADDDONTWAITUSE_FDUNSUBSCRIBEEVENTSEVENT_HANDSHAKE_FAILED_NO_DETAILENETDOWNIPV6__all__TCP_KEEPALIVE_IDLEPROTOCOL_ERROR_ZAP_BAD_REQUEST_IDLINGERETIMEDOUTPLAIN_SERVERXREQXPUB_NODROPEVENT_ACCEPT_FAILEDROUTER_HANDOVERENETUNREACHVMCI_BUFFER_MIN_SIZEXPUB_MANUALPROTOCOL_ERROR_ZMTP_INVALID_METADATAPROTOCOL_ERROR_ZMTP_MALFORMED_COMMAND_INITIATEUPSTREAMVMCI_BUFFER_MAX_SIZEMOREENOTSOCKNOTIFY_CONNECTPROTOCOL_ERROR_ZAP_UNSPECIFIEDMULTICAST_HOPSSWAP__name__EVENT_HANDSHAKE_FAILED_PROTOCOLRECOVERY_IVL_MSECIO_THREADSENOBUFSPROTOCOL_ERROR_ZMTP_INVALID_SEQUENCEPOLLITEMS_DFLTLAST_ENDPOINTDELAY_ATTACH_ON_CONNECTIPC_FILTER_GIDEMSGSIZEROUTING_IDRCVHWMREQ_CORRELATEXPUB_WELCOME_MSGHANDSHAKE_IVLSCATTERSNDHWMDOWNSTREAMRECONNECT_IVL_MAXEINPROGRESS__test__EVENT_CONNECT_DELAYEDDRAFT_APITHREAD_NAME_PREFIXSNDMOREQUEUEMULTICAST_LOOPTCP_ACCEPT_FILTERCONNECT_TIMEOUTNULLZAP_ENFORCE_DOMAINXREPEADDRNOTAVAILTCP_KEEPALIVESHAREDRATEEVENT_HANDSHAKE_SUCCEEDEDVERSION_MAJORGSSAPI_SERVICE_PRINCIPALCLIENTMAXMSGSIZEMAX_SOCKETS_DFLTPROTOCOL_ERROR_ZMTP_MALFORMED_COMMAND_ERRORAFFINITYGSSAPI_NT_USER_NAMEIPC_FILTER_UIDSTREAMMECHANISMTHREAD_AFFINITY_CPU_REMOVERCVTIMEONOTIFY_DISCONNECTSUBSCRIBEIPC_FILTER_PIDPROTOCOL_ERROR_ZMTP_MALFORMED_COMMAND_MESSAGEPROTOCOL_ERROR_ZMTP_MALFORMED_COMMAND_UNSPECIFIEDHEARTBEAT_TTLFORWARDERGSSAPI_PRINCIPALROUTER_BEHAVIORDEALERROUTER_NOTIFYEHOSTUNREACHEFSM0MQ Constants.THREAD_SAFEROUTER_MANDATORYENOMEMRCVBUFEVENT_ACCEPTEDTCP_KEEPALIVE_CNTGSSAPI_SERVERTHREAD_PRIORITY_DFLTPROTOCOL_ERROR_ZMTP_KEY_EXCHANGEXPUB_VERBOSEEMTHREADPROTOCOL_ERROR_ZMTP_MALFORMED_COMMAND_READYENOCOMPATPROTOEFAULTPOLLERRSOCKS_PROXYPROTOCOL_ERROR_ZAP_BAD_VERSIONENOTSUPGSSAPIVMCI_CONNECT_TIMEOUTEVENT_LISTENINGPROTOCOL_ERROR_ZAP_INVALID_STATUS_CODEHEARTBEAT_IVLDISHEVENT_CONNECT_RETRIEDFAIL_UNROUTABLECONNECT_ROUTING_IDZAP_DOMAINENOTCONN
Source: Cerberus.exe, 00000015.00000002.2345259529.00007FFA2B42B000.00000002.00000001.01000000.00000044.sdmp Binary or memory string: VMCI_CONNECT_TIMEOUT
Source: Cerberus.exe, 00000015.00000002.2345259529.00007FFA2B42B000.00000002.00000001.01000000.00000044.sdmp Binary or memory string: VMCI_BUFFER_SIZE
Source: Cerberus.exe, 00000015.00000002.2345259529.00007FFA2B42B000.00000002.00000001.01000000.00000044.sdmp Binary or memory string: VMCI_BUFFER_MIN_SIZE
Source: Cerberus.exe, 00000003.00000002.1266636650.000001A9AF8EB000.00000004.00000020.00020000.00000000.sdmp, Cerberus.exe, 00000015.00000002.2288470836.000001654F562000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: Cerberus.exe, 00000015.00000002.2345259529.00007FFA2B42B000.00000002.00000001.01000000.00000044.sdmp Binary or memory string: XSUBMCAST_LOOPBINDTODEVICEPROBE_ROUTERMAX_SOCKETSPAIRTHREAD_SCHED_POLICYPROTOCOL_ERROR_ZMTP_MECHANISM_MISMATCHEPROTONOSUPPORTPOLLOUTENETRESETEVENT_CLOSE_FAILED__main__PROTOCOL_ERROR_ZMTP_UNEXPECTED_COMMANDECONNRESETMULTICAST_MAXTPDUCURVE_PUBLICKEYPOLLPRIRECOVERY_IVLIO_THREADS_DFLTPROTOCOL_ERROR_ZMTP_CRYPTOGRAPHICTCP_KEEPALIVE_INTVLCURVE_SERVERKEYVMCI_BUFFER_SIZEGSSAPI_PRINCIPAL_NAMETYPECONNECT_RIDPLAINROUTER_RAWEADDRINUSE@
Source: Cerberus.exe, 00000015.00000002.2345259529.00007FFA2B42B000.00000002.00000001.01000000.00000044.sdmp Binary or memory string: VMCI_BUFFER_MAX_SIZE
Source: Cerberus.exe, 00000003.00000002.1299666174.00007FFA2C278000.00000008.00000001.01000000.00000017.sdmp, Cerberus.exe, 00000015.00000002.2347052013.00007FFA2BB68000.00000008.00000001.01000000.0000003F.sdmp Binary or memory string: .?AVQEmulationPaintEngine@@
Source: C:\Users\user\Desktop\Cerberus.exe Process created: C:\Users\user\Desktop\Cerberus.exe "C:\Users\user\Desktop\Cerberus.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Process created: C:\Users\user\Desktop\Cerberus.exe "C:\Users\user\Desktop\Cerberus.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PIL VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\imageformats VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\numpy VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\translations VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\translations VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\translations VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\translations VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography-2.8.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography-2.8.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography-2.8.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography-2.8.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography-2.8.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\cryptography-2.8.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst\include VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst\include VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst\include VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\parsers\rst\include VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\latex2e VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes\default VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes\default VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes\default VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html\themes\medium-black VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\docutils\writers\s5_html VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\importlib_metadata-4.13.0.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\setuptools-67.2.0.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\wheel-0.38.4.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\wheel-0.38.4.dist-info VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\ucrtbase.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\_ctypes.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\_bz2.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\_lzma.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\_hashlib.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\6mowp8ve VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\tmp2_46y0md VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\win32api.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pyexpat.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\_socket.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\select.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\_queue.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\bin\Qt5Core.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtWidgets.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\sip.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtCore.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\QtGui.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\libzmq.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\constants.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\error.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\message.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\context.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\utils.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_device.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\zmq\backend\cython\_proxy_steerable.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\pywin32_system32 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\yaml VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\yaml VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\yaml VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\yaml\_yaml.cp37-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\yaml VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\tmp2_46y0md VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\tmp2_46y0md\gen_py\__init__.py VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\tmp2_46y0md\gen_py\dicts.dat VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\Desktop\Cerberus.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qminimal.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qoffscreen.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qwebgl.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI7402\PyQt5\Qt5\plugins\platforms\qwindows.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cerberus.exe Code function: 3_2_00007FFA2C008138 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 3_2_00007FFA2C008138
Source: C:\Users\user\Desktop\Cerberus.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs