C&CMembers
C&C

WinAuthority’s run-labelled request points to a specific endpoint

Sandbox reports show the signed executable sending an application- and version-specific request to s.91toolbox.com. A small HTTP response and process-linked local artifacts support launch reporting as the best interpretation, but the records do not show server instructions or a command channel.

Oct 8, 2026, 07:32 (UTC+9)Last seenOct 8, 2026Severity100ByCTX TeamIOC14MITRE48

A signed Windows executable sent an HTTP request that described its own activity as action=run, identified the application as winauth, and supplied a version matching the file’s reported version. What was the receiving server doing: collecting application activity, delivering instructions, or serving some other purpose? The sandbox records examined by CTX Threat Intelligence support a specific answer: WinAuthority.exe made a run-labelled request to s.91toolbox.com, while leaving…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence