Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

307 lab records

Latest note ·

Arma dei Carabinieri Virus

The *Arma dei Carabinieri* message is a banner that may appear on your PC, attempting to mimic notifications from Italy's national gendarmerie. Cybercriminals use their name and authority to convince users from Italy into...

Field note ·

PrimeLookup Extension Removal Guide

PrimeLookup is a Chrome extension that may unexpectedly appear among your browser's add-ons, causing your search...

Research log

02

Trojan:Script/Obfuse!MSR

Record ·

Trojan:Script/Obfuse!MSR is a generic detection of a malicious script that abuses command interpreters to execute commands or binaries. What distinguishes this threat from others...

03

What is the Hkbsse.exe Process?

Record ·

Hkbsse.exe is a name of a process related to Amadey Dropper, that you can observe while browsing through the system. This malware delivers other...

05

Trojan:Win32/Commandrob.A!ml Threat Analysis

Record ·

Trojan:Win32/Commandrob.A!ml is a heuristic detection associated with suspicious network activity. It may refer to a wide range of malicious programs, or be a false...

06

Azurestaticapps.net

Record ·

Azurestaticapps.net is a selection of pages registered on genuine Microsoft hosting, that try scaring the user by false malware infection claims. In fact, it...

07

Trojan:Win64/Zusy.CZ!MTB

Record ·

Trojan:Win64/Zusy.CZ!MTB is a detection of Microsoft Defender that can flag several different types of malware. Being a heuristic detection, it can as well be...

08

Sec-tl Pop-Up Virus

Record ·

Sec-tl pop-up ads are malicious push notifications that parasite legitimate browser functionality. Fraudulent actors that stand behind this chain of websites earn money by...

10

First-tl Pop-Up Virus

Record ·

First-tl pop-up ads are malicious push notifications (like a Sec-tl sites) that parasite legitimate browser functionality. Fraudulent actors that stand behind this chain of...

13

Trojan:Win32/Fauppod!ml

Record ·

What does Fauppod!ml mean? Trojan:Win32/Fauppod!ml is a Microsoft Defender machine-learning detection. It does not name one exact malware family; it means the file looks...

14

JsTimer Extension Virus – Easy Removal Instructions

Record ·

JsTimer is a malicious browser extension detected in various browsers, predominantly targeting users through dubious websites. This extension engages in peculiar behavior by blocking...

AI Assistant

Hello! 👋 How can I help you today?