Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

310 lab records

Latest note ·

TrojanDownloader:HTML/Elshutilo

TrojanDownloader:HTML/Elshutilo is script-based malware designed to download additional payloads onto the target system. Since detection is based on threat behavior rather than a signature, it can sometimes result in false positives. Let me explain...

Research log

01

PUABundler:Win32/MediaGet: What It Is and How to Remove It

Record ·

PUABundler:Win32/MediaGet is a Microsoft Defender detection for MediaGet-related bundled software. MediaGet is commonly associated with torrent/pirated-content workflows and may install extra components or unwanted...

02

PrimeLookup Extension Removal Guide

Record ·

PrimeLookup is a Chrome extension that may unexpectedly appear among your browser's add-ons, causing your search queries to be redirected. As a browser hijacker,...

05

Trojan:Script/Obfuse!MSR

Record ·

Trojan:Script/Obfuse!MSR is a generic detection of a malicious script that abuses command interpreters to execute commands or binaries. What distinguishes this threat from others...

06

What is the Hkbsse.exe Process?

Record ·

Hkbsse.exe is a name of a process related to Amadey Dropper, that you can observe while browsing through the system. This malware delivers other...

08

Trojan:Win32/Commandrob.A!ml Threat Analysis

Record ·

Trojan:Win32/Commandrob.A!ml is a heuristic detection associated with suspicious network activity. It may refer to a wide range of malicious programs, or be a false...

09

Azurestaticapps.net

Record ·

Azurestaticapps.net is a selection of pages registered on genuine Microsoft hosting, that try scaring the user by false malware infection claims. In fact, it...

10

Trojan:Win64/Zusy.CZ!MTB

Record ·

Trojan:Win64/Zusy.CZ!MTB is a detection of Microsoft Defender that can flag several different types of malware. Being a heuristic detection, it can as well be...

11

Sec-tl Pop-Up Virus

Record ·

Sec-tl pop-up ads are malicious push notifications that parasite legitimate browser functionality. Fraudulent actors that stand behind this chain of websites earn money by...

13

First-tl Pop-Up Virus

Record ·

First-tl pop-up ads are malicious push notifications (like a Sec-tl sites) that parasite legitimate browser functionality. Fraudulent actors that stand behind this chain of...

16

Trojan:Win32/Fauppod!ml

Record ·

What does Fauppod!ml mean? Trojan:Win32/Fauppod!ml is a Microsoft Defender machine-learning detection. It does not name one exact malware family; it means the file looks...

AI Assistant

Hello! 👋 How can I help you today?