Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

305 lab records

Latest note ·

UC Browser – Is it Legit? Analysis & Verdict

While browsing the Web, you can at some point find yourself with an installer file for a program called UC Browser. This dubious program appears as a normal web browser, although it has some...

Field note ·

Trojan:Script/Obfuse!MSR

Trojan:Script/Obfuse!MSR is a generic detection of a malicious script that abuses command interpreters to execute commands...

Research log

01

What is the Hkbsse.exe Process?

Record ·

Hkbsse.exe is a name of a process related to Amadey Dropper, that you can observe while browsing through the system. This malware delivers other...

03

Trojan:Win32/Commandrob.A!ml Threat Analysis

Record ·

Trojan:Win32/Commandrob.A!ml is a heuristic detection associated with suspicious network activity. It may refer to a wide range of malicious programs, or be a false...

04

Azurestaticapps.net

Record ·

Azurestaticapps.net is a selection of pages registered on genuine Microsoft hosting, that try scaring the user by false malware infection claims. In fact, it...

05

Trojan:Win64/Zusy.CZ!MTB

Record ·

Trojan:Win64/Zusy.CZ!MTB is a detection of Microsoft Defender that can flag several different types of malware. Being a heuristic detection, it can as well be...

06

Sec-tl Pop-Up Virus

Record ·

Sec-tl pop-up ads are malicious push notifications that parasite legitimate browser functionality. Fraudulent actors that stand behind this chain of websites earn money by...

08

First-tl Pop-Up Virus

Record ·

First-tl pop-up ads are malicious push notifications (like a Sec-tl sites) that parasite legitimate browser functionality. Fraudulent actors that stand behind this chain of...

11

Trojan:Win32/Fauppod!ml

Record ·

What does Fauppod!ml mean? Trojan:Win32/Fauppod!ml is a Microsoft Defender machine-learning detection. It does not name one exact malware family; it means the file looks...

12

JsTimer Extension Virus – Easy Removal Instructions

Record ·

JsTimer is a malicious browser extension detected in various browsers, predominantly targeting users through dubious websites. This extension engages in peculiar behavior by blocking...

15

Trojan:Win64/Reflo.HNS!MTB

Record ·

Win64/Reflo.HNS!MTB is a detection of a malware sample that aims at stealing confidential information. It usually spreads through game mods and works as quietly...

16

Check-tl-ver Pop-Up Virus

Record ·

Analysis shows a hike in the number of malicious pop-ups that come from Check-tl-ver websites. It is a rather common strategy of aggressive marketing...

AI Assistant

Hello! 👋 How can I help you today?