C&CMembers
C&C

UninstallerTray requests reveal a corroborated activity-reporting endpoint

Sandbox records tie UninstallerTray’s activity-labelled HTTP requests to DNS and port-80 traffic, making its destination more than an incidental address. The requests resemble WinAuthority’s reporting pattern, but neither the traffic nor the matching replies establish a command channel or shared server control.

Oct 11, 2026, 00:28 (UTC+9)Last seenOct 11, 2026Severity100ByCTX TeamActorGroup123Venus 121IOC16MITRE52

An executable named UninstallerTray.exe appeared in a sandbox process tree while the same report recorded HTTP requests describing application activity: action=run and action=nowork. The requests went to s.jyrich.com/deep, carried a module version matching the file’s version, and included two identifier fields. Was this an isolated reporting mechanism, or did it resemble the behavior already documented for WinAuthority? The comparison is substantive.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence