Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

305 lab records

Latest note ·

Trojan:PowerShell/CoinStealer.RP!MTB

Trojan:PowerShell/CoinStealer.RP!MTB is a detection of Microsoft Defender, that normally flags malware that can steal cryptocurrency wallets. You may see it popping up after downloading a program from the Web or running a dodgy PowerShell...

Field note ·

PUA:Win32/SBYinYing

PUA:Win32/SBYinYing is a potentially unwanted application (PUA) that is often bundled with certain cracked games. It...

Field note ·

Trojan:Win32/Qhosts

Trojan:Win32/Qhosts is malware that provides remote access to the target system and modifies the Hosts file....

Research log

01

PUABundler:Win32/YandexBundled

Record ·

PUABundler:Win32/YandexBundled is a detection of potentially unwanted application (PUA) associated with the Russian company Yandex. It is typically distributed as bundled software with repackaged...

04

Trojan:BAT/PSRunner.VS!MSR

Record ·

Trojan:BAT/PSRunner.VS!MSR is a detection of malware that executes malicious commands on a compromised system. It does not do much hurt by itself and rather...

06

CSRF (Cross-Site Request Forgery) vs XSS

Record ·

Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) is an attack targeting vulnerabilities in computer security, posing significant risks to user information and accounts. It...

08

Trojan:Script/Downloader!MSR: Meaning and Removal Guide

Record ·

Trojan:Script/Downloader!MSR is a Microsoft Defender alert for a script that can download another payload. Check the source, quarantine status, false-positive signs, and leftover persistence...

11

Fake Instagram Hacking Services

Record ·

Instagram hacking scams is an old-new direction of online fraud that targets people who want to get into someone’s accounts on social media. Frauds...

12

Stopabit Virus

Record ·

Stopabit is an unwanted application that has almost no useful functionality. Users can see its promotions as a useful tool for screen time control,...

14

Bloom.exe

Record ·

Bloom.exe is a malicious miner that masquerades as a legitimate process. Its job is to use the victim's device to mine cryptocurrency for con...

AI Assistant

Hello! 👋 How can I help you today?