Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

305 lab records

Latest note ·

Contacto Ransomware

Contacto virus is a newly identified ransomware strain that encrypts victims’ files and demands a ransom for their decryption. We identified this sample on January 7, 2025, and made a comprehensive analysis of the...

Field note ·

Are AI Deepnude Sites Safe?

AI deepnude sites can expose photos, accounts, payments, installs, and consent-sensitive images. Check privacy, scam, malware,...

Field note ·

MicrosoftHost.exe

MicrosoftHost.exe is a malicious process that the malware creates to disguise itself as a benign process....

Field note ·

AlienWare Ransomware

AlienWare is a type of ransomware designed to lock your files and hold them hostage until...

Research log

01

Trojan:Win32/Pomal!rfn Removal

Record ·

Defender flagged Trojan:Win32/Pomal!rfn? Learn how to check the file path, source, signature, false-positive signs, MSERT scan, and safe removal steps.

02

Novalock Ransomware

Record ·

Novalock is a sophisticated form of malware designed to encrypt your files and then demand payment for their release. It belongs to the Globeimposter...

03

Locklocklock Ransomware

Record ·

Locklocklock is a ransomware virus designed to lock your files and demand payment to restore access. Victims can identify encrypted files by the addition...

06

Brad Garlinghouse Crypto Giveaway Scam Explained

Record ·

Brad Garlinghouse Crypto Giveaway is a scam campaign that masquerades as a cryptocurrency giveaway. It falsely claimed to be organized by Ripple Foundation with...

07

Shougnoboassi.net Redirect Virus

Record ·

Shougnoboassi.net is a website that you may notice appearing in your web browser. It shows a human verification button, and upon interaction redirects the...

08

Skyjem.com

Record ·

Skyjem.com is a questionable search engine that you may see appearing in the browser for no obvious reason. Its search results are questionable and...

09

Ledger Recovery Phrase Verification Scam

Record ·

“Ledger Recovery Phrase Verification” is a scam email that targets non-vigilant users. Its goal is to trick users into writing down their recovery phrase...

11

Trojan:PowerShell/Malscript!MSR

Record ·

Trojan:PowerShell/Malscript!MSR refers to a detection linked to malicious script activity. This type of malware typically exploits the system console interface to download and run...

12

TrojanDownloader:HTML/Elshutilo

Record ·

TrojanDownloader:HTML/Elshutilo is script-based malware designed to download additional payloads onto the target system. Since detection is based on threat behavior rather than a signature,...

14

Aruba.it Email Scam

Record ·

The Aruba.it email scam is a phishing campaign using fake emails that appear to be from Aruba S.p.A., a well-known Italian company providing domain...

15

Arma dei Carabinieri Virus

Record ·

The *Arma dei Carabinieri* message is a banner that may appear on your PC, attempting to mimic notifications from Italy's national gendarmerie. Cybercriminals use...

16

Trojan:Win32/Offloader.EA!MTB

Record ·

Trojan:Win32/Offloader.EA!MTB is malware designed to establish unauthorized access to a target system or deliver a payload of additional malware. This detection is sometimes associated...

AI Assistant

Hello! 👋 How can I help you today?