
UninstallerTray requests reveal a corroborated activity-reporting endpoint
Sandbox records tie UninstallerTray’s activity-labelled HTTP requests to DNS and port-80 traffic, making its destination more than an incidental address. The requests resemble WinAuthority’s reporting pattern, but neither the traffic nor the matching replies establish a command channel or shared server control.
An executable named UninstallerTray.exe appeared in a sandbox process tree while the same report recorded HTTP requests describing application activity: action=run and action=nowork. The requests went to s.jyrich.com/deep, carried a module version matching the file’s version, and included two identifier fields. Was this an isolated reporting mechanism, or did it resemble the behavior already documented for WinAuthority? The comparison is substantive.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read