Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

310 lab records

Latest note ·

JsTimer Extension Virus – Easy Removal Instructions

JsTimer is a malicious browser extension detected in various browsers, predominantly targeting users through dubious websites. This extension engages in peculiar behavior by blocking access to the Chrome Web Store, which, although seemingly trivial...

Field note ·

Trojan:PowerShell/CoinStealer.RP!MTB

Trojan:PowerShell/CoinStealer.RP!MTB is a detection of Microsoft Defender, that normally flags malware that can steal cryptocurrency wallets....

Field note ·

PUABundler:Win32/DriverPack

PUABundler:Win32/DriverPack is potentially unwanted software that claims to install or update drivers. In fact, it floods...

Field note ·

Virus Alert (05261) Scam

"Virus Alert (05261)" is a scam pop-up message you can see on a website that looks...

Research log

01

Movidown Unwanted Application

Record ·

Movidown is an Unwanted Application that initially mimics a utility for controlling fan speed. However, beneath this shell, it has the capabilities of a...

03

PUA:Win32/SBYinYing

Record ·

PUA:Win32/SBYinYing is a potentially unwanted application (PUA) that is often bundled with certain cracked games. It may display ads to users or redirect them...

05

Trojan:Win32/Qhosts

Record ·

Trojan:Win32/Qhosts is malware that provides remote access to the target system and modifies the Hosts file. It is primarily distributed through illegal activation tools...

06

PUABundler:Win32/YandexBundled

Record ·

PUABundler:Win32/YandexBundled is a detection of potentially unwanted application (PUA) associated with the Russian company Yandex. It is typically distributed as bundled software with repackaged...

09

Trojan:BAT/PSRunner.VS!MSR

Record ·

Trojan:BAT/PSRunner.VS!MSR is a detection of malware that executes malicious commands on a compromised system. It does not do much hurt by itself and rather...

11

CSRF (Cross-Site Request Forgery) vs XSS

Record ·

Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) is an attack targeting vulnerabilities in computer security, posing significant risks to user information and accounts. It...

13

Trojan:Script/Downloader!MSR: Meaning and Removal Guide

Record ·

Trojan:Script/Downloader!MSR is a Microsoft Defender alert for a script that can download another payload. Check the source, quarantine status, false-positive signs, and leftover persistence...

16

Fake Instagram Hacking Services

Record ·

Instagram hacking scams is an old-new direction of online fraud that targets people who want to get into someone’s accounts on social media. Frauds...

AI Assistant

Hello! 👋 How can I help you today?