
WinAuthority’s run-labelled request points to a specific endpoint
Sandbox reports show the signed executable sending an application- and version-specific request to s.91toolbox.com. A small HTTP response and process-linked local artifacts support launch reporting as the best interpretation, but the records do not show server instructions or a command channel.
A signed Windows executable sent an HTTP request that described its own activity as action=run, identified the application as winauth, and supplied a version matching the file’s reported version. What was the receiving server doing: collecting application activity, delivering instructions, or serving some other purpose? The sandbox records examined by CTX Threat Intelligence support a specific answer: WinAuthority.exe made a run-labelled request to s.91toolbox.com, while leaving…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read