C&CMembers
C&C

One executable appeared behind several application names

Sandbox records show files in a launcher directory and a browser installer directory with the exact hash of the analyzed executable. The matching content supports placement under different application-related names, not separate launches or a confirmed command-and-control exchange.

Oct 9, 2026, 15:34 (UTC+9)Last seenOct 9, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC49MITRE17RegionsID

A Windows executable appeared in a sandbox’s file outputs under both a CUAssistant launcher path and a Chrome installer path—with exactly the same SHA-256 as the file submitted for analysis. That raises a more useful question than the filenames alone can answer: were these separate software components, or was one executable’s content being placed behind several application-related names? The records support the latter interpretation for several outputs.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence