
Sandbox links written executable to logon target, records port-25 contacts
A sandbox report records a file written to a Windows user profile and a Run entry pointing to that path. Separate observations show the submitted sample making outbound port-25 contacts, but do not show the Run entry launching the file or any email being sent.
A sandbox report records daxixreameam.exe being written into a Windows user profile and a user-logon registry entry pointing to that same path. That relationship makes the filename more than an incidental artifact: it was both a recorded file-write destination and the target of a launch setting. But what was the executable being positioned to do? Separate network observations for the submitted sample show outbound contacts on TCP port 25, the port used by SMTP servers.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read