IOC Report
Apache ActiveMQ.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Apache ActiveMQ.exe
"C:\Users\user\Desktop\Apache ActiveMQ.exe"
malicious

Domains

Name
IP
Malicious
mvs05.zyns.com
81.19.82.2

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
unkown
page readonly
CFF000
stack
page read and write
80C000
heap
page read and write
190000
heap
page read and write
80000
heap
page read and write
400000
unkown
page readonly
160000
heap
page read and write
60C000
stack
page read and write
408000
unkown
page read and write
409000
unkown
page write copy
407000
unkown
page readonly
407000
unkown
page readonly
401000
unkown
page execute read
813000
heap
page read and write
408000
unkown
page write copy
405000
unkown
page readonly
806000
heap
page read and write
AFF000
stack
page read and write
401000
unkown
page execute read
1F0000
heap
page read and write
800000
heap
page read and write
405000
unkown
page readonly
There are 12 hidden memdumps, click here to show them.