Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

305 lab records

Latest note ·

PUA:Win32/Caypnamer.A!ml: What It Is and Removal

PUA:Win32/Caypnamer.A!ml is a Microsoft Defender detection that should be judged by the affected file path, source, signature, and behavior, not by the name alone. Microsoft says Defender detects and removes this threat and lists...

Field note ·

Internet Is A Dangerous Place

The "Internet Is A Dangerous Place" scam is a novel type of threatening email message that...

Research log

04

Win.MxResIcn.Heur.Gen

Record ·

Antivirus engine of MaxSecure, a well-known cybersecurity vendor, currently shows massive amounts of false positive detection with the name Win.MxResIcn.Heur.Gen. It touches numerous legitimate...

05

IP Stresser: Legal Test or DDoS Booter?

Record ·

An IP stresser is safe only for systems you own or have written permission to test. Learn free-stresser red flags, DDoS booter risks, and...

06

Meduza Stealer

Record ·

The Malware world evolves constantly, and it would be reckless to ignore newcomers and their potential. Meduza Stealer appears to be a pretty potent...

11

RegAsm.exe: Safe or Malware?

Record ·

RegAsm.exe is a legitimate Microsoft .NET tool, but malware can imitate or abuse it. Check the path, signature, command line, startup entries, and blocked...

12

What Is TextInputHost.exe?

Record ·

TextInputHost.exe is usually a safe Microsoft Windows input process. Learn how to verify its path and signature, fix high GPU usage or system errors,...

15

Sniffing vs Spoofing

Record ·

Learn the difference between sniffing and spoofing, how attackers use traffic capture and fake identity, and how to protect accounts, devices, and networks.

AI Assistant

Hello! 👋 How can I help you today?