Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

307 lab records

Latest note ·

Nnice Ransomware

Nnice ransomware is a malware strain that aims at encrypting user files and demanding ransom payment for their decryption. Detected on January 14, 2025, it presumably targets individuals and small businesses. Upon the encryption,...

Field note ·

Are AI Deepnude Sites Safe?

AI deepnude sites can expose photos, accounts, payments, installs, and consent-sensitive images. Check privacy, scam, malware,...

Research log

01

MicrosoftHost.exe

Record ·

MicrosoftHost.exe is a malicious process that the malware creates to disguise itself as a benign process. Users may witness high CPU load coming from...

02

AlienWare Ransomware

Record ·

AlienWare is a type of ransomware designed to lock your files and hold them hostage until you pay up. It’s sneaky and frustrating, leaving...

03

Trojan:Win32/Pomal!rfn Removal

Record ·

Defender flagged Trojan:Win32/Pomal!rfn? Learn how to check the file path, source, signature, false-positive signs, MSERT scan, and safe removal steps.

04

Novalock Ransomware

Record ·

Novalock is a sophisticated form of malware designed to encrypt your files and then demand payment for their release. It belongs to the Globeimposter...

05

Locklocklock Ransomware

Record ·

Locklocklock is a ransomware virus designed to lock your files and demand payment to restore access. Victims can identify encrypted files by the addition...

08

Brad Garlinghouse Crypto Giveaway Scam Explained

Record ·

Brad Garlinghouse Crypto Giveaway is a scam campaign that masquerades as a cryptocurrency giveaway. It falsely claimed to be organized by Ripple Foundation with...

09

Shougnoboassi.net Redirect Virus

Record ·

Shougnoboassi.net is a website that you may notice appearing in your web browser. It shows a human verification button, and upon interaction redirects the...

10

Skyjem.com

Record ·

Skyjem.com is a questionable search engine that you may see appearing in the browser for no obvious reason. Its search results are questionable and...

11

Ledger Recovery Phrase Verification Scam

Record ·

“Ledger Recovery Phrase Verification” is a scam email that targets non-vigilant users. Its goal is to trick users into writing down their recovery phrase...

13

Trojan:PowerShell/Malscript!MSR

Record ·

Trojan:PowerShell/Malscript!MSR refers to a detection linked to malicious script activity. This type of malware typically exploits the system console interface to download and run...

14

TrojanDownloader:HTML/Elshutilo

Record ·

TrojanDownloader:HTML/Elshutilo is script-based malware designed to download additional payloads onto the target system. Since detection is based on threat behavior rather than a signature,...

16

Aruba.it Email Scam

Record ·

The Aruba.it email scam is a phishing campaign using fake emails that appear to be from Aruba S.p.A., a well-known Italian company providing domain...

AI Assistant

Hello! 👋 How can I help you today?