Contacto Ransomware
Contacto virus is a newly identified ransomware strain that encrypts victims’ files and demands a ransom for their decryption. We identified this sample on January 7, 2025, and made a comprehensive analysis of the...
Threat research notebook
Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.
305 lab recordsContacto virus is a newly identified ransomware strain that encrypts victims’ files and demands a ransom for their decryption. We identified this sample on January 7, 2025, and made a comprehensive analysis of the...
AI deepnude sites can expose photos, accounts, payments, installs, and consent-sensitive images. Check privacy, scam, malware,...
MicrosoftHost.exe is a malicious process that the malware creates to disguise itself as a benign process....
AlienWare is a type of ransomware designed to lock your files and hold them hostage until...
Defender flagged Trojan:Win32/Pomal!rfn? Learn how to check the file path, source, signature, false-positive signs, MSERT scan, and safe removal steps.
Novalock is a sophisticated form of malware designed to encrypt your files and then demand payment for their release. It belongs to the Globeimposter...
Locklocklock is a ransomware virus designed to lock your files and demand payment to restore access. Victims can identify encrypted files by the addition...
Microsoft Defender found Trojan:Win32/Patched? Learn what the alert means, when a patched file can be a false positive, and how to remove it safely.
SUPERLOCK is a ransomware infection that aims at blocking access to the files and demanding a payment for getting them back. Users can distinguish...
Brad Garlinghouse Crypto Giveaway is a scam campaign that masquerades as a cryptocurrency giveaway. It falsely claimed to be organized by Ripple Foundation with...
Shougnoboassi.net is a website that you may notice appearing in your web browser. It shows a human verification button, and upon interaction redirects the...
Skyjem.com is a questionable search engine that you may see appearing in the browser for no obvious reason. Its search results are questionable and...
“Ledger Recovery Phrase Verification” is a scam email that targets non-vigilant users. Its goal is to trick users into writing down their recovery phrase...
Trojan:PDF/Phish.A means Defender found a suspicious PDF phishing link. Learn when it is risky, how to remove it, and what to scan after a...
Trojan:PowerShell/Malscript!MSR refers to a detection linked to malicious script activity. This type of malware typically exploits the system console interface to download and run...
TrojanDownloader:HTML/Elshutilo is script-based malware designed to download additional payloads onto the target system. Since detection is based on threat behavior rather than a signature,...
Opera GX is legitimate when downloaded from Opera, but fake OperaGXSetup.exe pop-ups, warez redirects, bundle installers, and privacy settings need a careful check.
The Aruba.it email scam is a phishing campaign using fake emails that appear to be from Aruba S.p.A., a well-known Italian company providing domain...
The *Arma dei Carabinieri* message is a banner that may appear on your PC, attempting to mimic notifications from Italy's national gendarmerie. Cybercriminals use...
Trojan:Win32/Offloader.EA!MTB is malware designed to establish unauthorized access to a target system or deliver a payload of additional malware. This detection is sometimes associated...