Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

297 lab records

Latest note ·

Trojan:Win32/Pomal!rfn Removal

Defender flagged Trojan:Win32/Pomal!rfn? Learn how to check the file path, source, signature, false-positive signs, MSERT scan, and safe removal steps.

Field note ·

Skyjem.com

Skyjem.com is a questionable search engine that you may see appearing in the browser for no...

Research log

01

Ledger Recovery Phrase Verification Scam

Record ·

“Ledger Recovery Phrase Verification” is a scam email that targets non-vigilant users. Its goal is to trick users into writing down their recovery phrase...

03

Trojan:PowerShell/Malscript!MSR

Record ·

Trojan:PowerShell/Malscript!MSR refers to a detection linked to malicious script activity. This type of malware typically exploits the system console interface to download and run...

04

TrojanDownloader:HTML/Elshutilo

Record ·

TrojanDownloader:HTML/Elshutilo is script-based malware designed to download additional payloads onto the target system. Since detection is based on threat behavior rather than a signature,...

06

Aruba.it Email Scam

Record ·

The Aruba.it email scam is a phishing campaign using fake emails that appear to be from Aruba S.p.A., a well-known Italian company providing domain...

07

Arma dei Carabinieri Virus

Record ·

The *Arma dei Carabinieri* message is a banner that may appear on your PC, attempting to mimic notifications from Italy's national gendarmerie. Cybercriminals use...

08

Trojan:Win32/Offloader.EA!MTB

Record ·

Trojan:Win32/Offloader.EA!MTB is malware designed to establish unauthorized access to a target system or deliver a payload of additional malware. This detection is sometimes associated...

10

PUA:Win32/WebCompanion: Meaning and Removal

Record ·

PUA:Win32/WebCompanion is a Defender detection for Adaware Web Companion or related bundled installs. Remove unwanted browser and system changes.

12

PUABundler:Win32/MediaGet: What It Is and How to Remove It

Record ·

PUABundler:Win32/MediaGet is a Microsoft Defender detection for MediaGet-related bundled software. MediaGet is commonly associated with torrent/pirated-content workflows and may install extra components or unwanted...

13

PrimeLookup Extension Removal Guide

Record ·

PrimeLookup is a Chrome extension that may unexpectedly appear among your browser's add-ons, causing your search queries to be redirected. As a browser hijacker,...

16

Trojan:Script/Obfuse!MSR

Record ·

Trojan:Script/Obfuse!MSR is a generic detection of a malicious script that abuses command interpreters to execute commands or binaries. What distinguishes this threat from others...

AI Assistant

Hello! 👋 How can I help you today?